diff --git a/Oceanlotus/hunting-rule.txt b/Oceanlotus/hunting-rule.txt new file mode 100644 index 0000000..90a1c33 --- /dev/null +++ b/Oceanlotus/hunting-rule.txt @@ -0,0 +1,2 @@ +imports:”GdipGetImageWidth” AND imports:”WriteProcessMemory” AND imports:”GdipCreateBitmapFromFile” +AND tag:pedll